Governance

Each operating entity maintains an inventory of systems, processing purposes, recipients, retention rules, vendors, and jurisdictional obligations. High-risk changes require privacy and security review.

Protection by design

  • Tenant and country-cell isolation with least-privilege access.
  • Encryption in transit, protected secrets, private uploads, audit records, and redacted logs.
  • Short-lived credentials, optional 2FA and device controls, rate limits, provider signatures, and anti-replay protections.
  • Backups, restoration procedures, key rotation, monitoring, incident response, and controlled deletion.

Your rights

Authenticated export and deletion-request workflows are available. Deletion anonymizes eligible personal fields while retaining financial, fraud, safety, dispute, and legal records for required periods. Contact support to challenge or clarify a result.

Accountability

Access is role-restricted and auditable. Providers receive only required information and are reviewed contractually and operationally. Material incidents follow documented assessment, containment, recovery, and notification procedures.